20
Stanford Forensics Lab: a case study Glynn Edwards, RBMS, Baton Rouge, LA - 2011 Digital Forensics at Stanford University Libraries Michael Olson Digital Collections Project Manager [email protected]

Digital Forensics at Stanford University Stanford

  • Upload
    others

  • View
    10

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Digital Forensics at Stanford University Stanford

Stanford Forensics Lab: a case study

Glynn Edwards, RBMS, Baton Rouge, LA - 2011

Digital Forensics at Stanford University Libraries

Michael OlsonDigital Collections Project [email protected]

Page 2: Digital Forensics at Stanford University Stanford

Topics

• The Collections

• Forensics Lab 

• AIMS (An Inter‐Institutional Model for Stewardship)

• Hypatia software development

• Other efforts of note (training, data mining)

Page 3: Digital Forensics at Stanford University Stanford

Collection Acquisitions in the 1990s

• Apple Computer Inc. records

• Douglas Engelbart papers

• Stephen Cabrinety collection

• By 2000, over 9,000 items of legacy computer media received as part of hybrid collections

Page 4: Digital Forensics at Stanford University Stanford

And More Collections

• Stephen Jay Gould (documents)

• Keith Henson papers re: to Project Xanadu (applications)

• Robert Creeley (email)

• Peter Koch (design files)

Stephen Jay Gould

Peter Rutledge Koch papers

Page 5: Digital Forensics at Stanford University Stanford

More collections, new challenges

Robert Creeley born-digital May 2011 addenda :•7 computers•3 zip drives•121 optical discs•422 3.5-inch floppy diskettes•1 Zip 250 USB Drive•1 Olympus Camedia CF/SmartMedia Reader•1 Olympus C-4000 Camedia Digital Camera & flash cards•1 20-gigabyte iPod

Robert Creeley

Page 6: Digital Forensics at Stanford University Stanford

FRED (Forensic Recovery Evidence Device: Digital Intelligence) Software: FTK suite (AccessData) ‐ EnCase

Page 7: Digital Forensics at Stanford University Stanford

Dear Peter,

Unfortunately we do not manufacture any motherboards now a days which can support the 5.25 floppy. The interface are different than 3.5 and they are becoming obsolete and are no longer available on the newer motherboards.

Page 8: Digital Forensics at Stanford University Stanford
Page 9: Digital Forensics at Stanford University Stanford

Capture Failure Statistics

• Stephen Jay Gould – 5 % 

• Robert Creeley – 6 %

• Xanadu hard disk drives – 67%

Page 10: Digital Forensics at Stanford University Stanford

AIMS Born‐Digital Collections: An Inter‐Institutional Model for Stewardship

Funded by the Andrew W. Mellon Foundation

University of VirginiaYale University

Hull University

Stanford University

Page 11: Digital Forensics at Stanford University Stanford

Hypatia

• Developed on Hydra technology stack:• Fedora

• Solr

• Blacklight

• Hypatia is a Hydra application for arranging, describing, and delivering born digital archival content

• Application under development – demo app by Oct. 2011

Page 12: Digital Forensics at Stanford University Stanford

Hypatia

• Wiki ‐https://wiki.duraspace.org/display/HYPAT/Home

• JIRA ‐https://jira.duraspace.org/browse/HYPAT

Page 13: Digital Forensics at Stanford University Stanford
Page 14: Digital Forensics at Stanford University Stanford

Additional Work of Note

• Training of Stanford library staff in forensic / logical capture as well as use of FTK

• Visualization of born digital collections• Robert Creeley Email Network Graph showing connection between Robert Creeley and poet Gerard Malanga – Elijah Meeks

• Data mining of sentiment in email archives ‐MUSE prototype software by Sudheendra Hangal, Computer Science PhD

Peter Rutledge Koch papers

Page 15: Digital Forensics at Stanford University Stanford
Page 16: Digital Forensics at Stanford University Stanford
Page 17: Digital Forensics at Stanford University Stanford

AccessData FTK

• Create New Case

• Technical Metadata Extracted by FTK

• View Files in “obsolete” File Formats

• View Image Files as Thumbnails

• Search for Restricted Files using Index / Pattern Search

• Flag Restricted Files as Privileged

• Change Column Settings to Include or Exclude Information

• Apply Filter to Items to be Displayed

• Arrange Files in Series / Subseries by Assigning Bookmarks

• See Files by Bookmarks

• Create and Assign Labels to Files 

• View Files by Labels 

Page 18: Digital Forensics at Stanford University Stanford

Creeley’s Email Network

Page 19: Digital Forensics at Stanford University Stanford

Email Mining on Peter Koch’s Emails

Page 20: Digital Forensics at Stanford University Stanford

Email Mining on Peter Koch’s Emails

http://suif.stanford.edu/~hangal/muse/